DOM-Based XSS Vulnerability in Dobase Shared Folder Image Gallery
CVE-2026-54165
6.4MEDIUM
What is CVE-2026-54165?
Dobase, a self-hosted workspace with available tools, is impacted by a stored DOM-based XSS vulnerability in the public shared-folder image gallery. In the affected versions, an attacker can manipulate a file's name due to lack of sanitation, allowing the payload to be injected into the page via the ERB-escaped data-name attribute. This poses a significant risk as any authenticated user sharing a folder can unknowingly spread the malicious code to anyone accessing the public share link. Notably, the global Content-Security-Policy is only report-only, which fails to mitigate the XSS, enabling execution of injected scripts.
Affected Version(s)
dobase < 2026.06.03
